session-search
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Utilizes local command-line tools
obsidian-wikiandgrepto perform session queries and check file metadata. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from historical agent session transcripts, creating a surface for indirect prompt injection.
- Ingestion points: Transcript files are read from disk based on paths retrieved from the
sessions-querycommand inSKILL.md(Step 4). - Boundary markers: No delimiters are defined to separate injected transcript content from the agent's primary instructions.
- Capability inventory: The skill has the ability to execute shell commands (
obsidian-wiki,grep) and run a Python script to parse file content. - Sanitization: Employs a Python script to filter for user-type turns, excludes metadata/sidechain turns, skips content beginning with
<tags, and truncates the retrieved content to 400 characters per turn.
Audit Metadata